Skip to main content

tuwunel_service/federation/
scheme.rs

1//! Adapters that build the `Input` for ruma's [`AuthScheme`] and
2//! [`PathBuilder`] traits from tuwunel's federation context.
3//!
4//! Federation endpoints span several auth/path-builder combinations
5//! (`ServerSignatures` + `VersionHistory`, `ServerSignatures` + `SinglePath`,
6//! and a handful of `NoAuthentication`/`NoAccessToken` variants). The
7//! generic-associated-type `Input<'a>` of each ruma trait varies per impl, so
8//! a single bound on `OutgoingRequest` cannot supply the right value uniformly.
9//! [`FedAuth`] and [`FedPath`] each accept tuwunel's federation context and
10//! return the appropriate `Input` for the concrete auth scheme or path builder
11//! at the call site.
12
13use std::borrow::Cow;
14
15use ruma::{
16	OwnedServerName,
17	api::{
18		SupportedVersions,
19		auth_scheme::{AuthScheme, NoAccessToken, NoAuthentication, SendAccessToken},
20		federation::authentication::{ServerSignatures, ServerSignaturesInput},
21		path_builder::{PathBuilder, SinglePath, VersionHistory},
22	},
23	signatures::Ed25519KeyPair,
24};
25
26/// Builds ruma authentication input from the local federation identity.
27///
28/// Implementations bridge each concrete [`AuthScheme`] to the common origin,
29/// destination, and signing-key context available to the service.
30pub trait FedAuth: AuthScheme {
31	/// Constructs the authentication input expected by this scheme.
32	///
33	/// Schemes that do not authenticate ignore some or all supplied context.
34	fn input(
35		origin: OwnedServerName,
36		dest: OwnedServerName,
37		keypair: &Ed25519KeyPair,
38	) -> <Self as AuthScheme>::Input<'_>;
39}
40
41impl FedAuth for NoAuthentication {
42	fn input(_: OwnedServerName, _: OwnedServerName, _: &Ed25519KeyPair) {}
43}
44
45impl FedAuth for NoAccessToken {
46	fn input(_: OwnedServerName, _: OwnedServerName, _: &Ed25519KeyPair) -> SendAccessToken<'_> {
47		SendAccessToken::None
48	}
49}
50
51impl FedAuth for ServerSignatures {
52	fn input(
53		origin: OwnedServerName,
54		dest: OwnedServerName,
55		keypair: &Ed25519KeyPair,
56	) -> ServerSignaturesInput<'_> {
57		ServerSignaturesInput::new(origin, dest, keypair)
58	}
59}
60
61/// Builds ruma path input from the remote server's supported versions.
62///
63/// Implementations adapt either a single fixed path or a versioned endpoint
64/// history to the same federation request path.
65pub trait FedPath: PathBuilder {
66	/// Constructs the path-builder input expected by this endpoint.
67	///
68	/// Single-path endpoints ignore the advertised version history.
69	fn input(supported: &SupportedVersions) -> <Self as PathBuilder>::Input<'_>;
70}
71
72impl FedPath for SinglePath {
73	fn input(_: &SupportedVersions) {}
74}
75
76impl FedPath for VersionHistory {
77	fn input(supported: &SupportedVersions) -> Cow<'_, SupportedVersions> {
78		Cow::Borrowed(supported)
79	}
80}